At a Glance
- Tasks: Lead application security and vulnerability management, driving strategy and continuous improvement.
- Company: Join Samsara, a pioneer in Connected Operations™ Cloud, transforming global industries.
- Benefits: Remote work, competitive salary, and rapid career development opportunities.
- Other info: Be part of a high-calibre team that celebrates success and supports each other.
- Why this job: Make a real-world impact while shaping the future of physical operations.
- Qualifications: 10+ years in cloud or security engineering with hands-on vulnerability management experience.
The predicted salary is between 63000 - 77000 £ per year.
Who we are
Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale.
About the role:
Samsara sits at the center of hardware, software, AI, and the physical world, processing 25+ trillion data points annually across thousands of connected devices. The Samsara Application Security team protects this vast footprint end-to-end, spanning cloud services, internal systems, and firmware running on IoT hardware in the field. As a Staff Application Security Engineer, you’ll drive the overarching technical direction for our application security and vulnerability management programs. This is a high-visibility role where you'll influence a broad surface area while retaining the flexibility to dive deep into critical domain focus areas as security priorities evolve. This is a remote position, open to candidates residing in the UK. Relocation assistance will not be provided for this role.
You should apply if:
- You want to impact the industries that run our world: Your efforts will result in real-world impact—helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely.
- You are the architect of your own career: If you put in the work, this role won't be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, and countless opportunities to experiment and master your craft in a hyper-growth environment.
- You're energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers.
- You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best.
In this role, you will:
- Lead the ongoing strategy, operation, and continuous improvement of Samsara's vulnerability management program, along with other core application security programs — not just execute against an existing process, but define what the process should be.
- Own and drive down mean time to remediate (MTTR) across the vulnerability backlog, as SLAs tighten.
- Build and champion automation and tooling that scale vulnerability detection and response across cloud, firmware/IoT, and corporate systems, rather than relying on manual, one-by-one review.
- Set technical and architectural direction for the program, translating leadership's strategic priorities into a concrete execution plan for the team.
- Drive remediation by building trust with engineering teams and providing clear, actionable guidance — partnering with technical program management on reporting rather than owning it directly.
- Mentor and level up other engineers on secure design and remediation practices, and be a technical voice other teams look to when priorities are unclear.
- Communicate risk and remediation tradeoffs to engineering leadership in terms they can act on, without owning the relationship end to end.
- Participate in security incident investigations involving high-profile vulnerabilities, assessing potential impact on Samsara's infrastructure.
- Be regularly on call to support critical vulnerability response.
- Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices.
Minimum requirements for the role:
- 10+ years of relevant experience as a cloud engineer or security engineer, including hands-on vulnerability management across a broad, multi-product enterprise environment.
- Proficiency in Go, Python, and JavaScript.
- Demonstrated ability to independently set technical and architectural direction for a security program, and to drive remediation across a broad, multi-surface environment without direct authority over the teams doing the fixing.
- Significant experience with modern vulnerability management tooling (e.g., Wiz, Semgrep) and deep familiarity with vulnerability scoring frameworks such as CVSS and EPSS.
- Strong AWS cloud services background.
- Deep understanding of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
- Hands-on use of AI/LLM tooling in your own security workflow — triage, detection logic, remediation drafting — plus credibility speaking to how AI is changing the threat landscape and the tooling available to address it.
An ideal candidate also has:
- Experience with C/C++, relevant to firmware and embedded systems.
- Background at a cloud-native, AI-forward company actively building agentic or AI-driven products.
- Experience with security automation platforms (e.g., Tines) and serverless frameworks (e.g., AWS Lambda).
- Experience integrating vulnerability management into modern CI/CD pipelines with a "shift-left" mentality.
- Experience spanning SaaS, firmware, and corporate IT security programs — not just one product line.
- Experience managing vulnerabilities within a FedRAMP-certified environment.
- Experience building, extending, or wiring up AI copilots/agents for security workflows (e.g., automated triage, remediation drafting).
Staff Application Security Engineer employer: Samsara
Samsara is an exceptional employer, offering a dynamic work culture in the heart of London that fosters innovation and collaboration. Employees benefit from comprehensive growth opportunities, competitive compensation, and a commitment to work-life balance, making it an ideal place for those seeking meaningful and rewarding careers in the legal field.
StudySmarter Expert Advice🤫
We think this is how you could land Staff Application Security Engineer
✨Join Local Tech Meetups
Get out there and mingle with fellow developers by joining local tech meetups. It’s a fantastic way to meet people who might be working at Samsara or know someone who does. Plus, you can pick up some trendy tech skills and trends while you're at it!
✨Contribute to Open Source Projects
Show off your coding chops by jumping into open-source projects. Not only does this give you practical experience, but it also gets you noticed in the dev community. You'll create a killer portfolio that speaks volumes about your skills to Samsara.
✨Tap into Online Developer Communities
Don’t underestimate the power of online developer communities like GitHub, Stack Overflow, and even Reddit. Participate in discussions, share your projects, and build your visibility. We can often find opportunities through these channels that can lead to a full-time gig at companies like Samsara.
✨Explore Job Boards Specifically for Tech Roles
Keep your eyes peeled on job boards that focus on tech roles. Sites like TechCareers or Stack Overflow Jobs can often have listings for companies like Samsara that might not show up on broader job sites. Make it a habit to check these regularly, and don’t hesitate to apply directly through our website!
We think you need these skills to ace Staff Application Security Engineer
Some tips for your application 🫡
Show off your coding skills:When applying for a software engineering role, it's super important to showcase your coding skills. Make sure your CV includes your tech stack, any relevant programming languages you’re comfortable with, and examples of projects you've worked on. If you have a GitHub profile, link it up! We love to see code in action.
Tailor your portfolio:For a full-time role, we’d expect to see some solid examples of your work in your portfolio. Make sure to include at least two or three projects that highlight your problem-solving skills and your ability to work with different technologies. Focus on the projects that are most relevant to the position at Samsara.
Craft a killer cover letter:Your cover letter is your chance to stand out—make it personal! Explain why you want to work at Samsara and how your skills align with the role. Show us your passion for software development. We dig enthusiastic candidates who understand the value of collaboration and continuous learning!
Be clear and concise:When it comes to writing your CV and cover letter, clarity is key. Avoid jargon that could confuse us and stick to simple, direct language. Highlight your achievements with quantifiable results where possible, and keep everything easy to read. A well-organised application goes a long way!
How to prepare for a job interview at Samsara
✨Brush Up on Your Coding Skills
For a full-time software engineering role, it's crucial that we stay sharp with our coding abilities. Expect technical questions that might involve solving problems on the spot or discussing algorithms. Practise on platforms like LeetCode or HackerRank to get comfortable with the types of questions that often come up.
✨Know Your Tools and Frameworks
Make sure we’re well-acquainted with the tools and technologies listed in the job description. Familiarise ourselves with any specific frameworks or programming languages mentioned. If Samsara uses React or Node.js, for instance, be ready to discuss how we’ve used them in previous projects or coursework.
✨Showcase Your Projects
Bring along a portfolio that highlights our best work. This could be code samples, GitHub repositories, or any side projects we’ve built. Make sure we can talk through our thought process for each project, especially the challenges we faced and how we solved them—this shows our problem-solving skills in action.
✨Prepare for Behavioural Questions
While technical skills are key, full-time positions also require cultural fit. Be ready to discuss our previous experiences and how we handle teamwork, conflict, and deadlines. Brush up on the STAR method—Situation, Task, Action, Result—to clearly articulate our past experiences when discussing how we've contributed to a team.